The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Security vulnerability httpoxy

Discussion in 'EasyApache' started by constella, Jul 18, 2016.

  1. constella

    constella Registered

    Joined:
    Nov 29, 2012
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Website Owner
    Hi,

    Do you know if the last WHM server is vulnerable with the httpoxy set of vulnerability?
    • CVE-2016-5385: PHP
    • CVE-2016-5386: Go
    • CVE-2016-5387: Apache HTTP Server
    • CVE-2016-5388: Apache Tomcat
    • CVE-2016-1000109: HHVM
    • CVE-2016-1000110: Python
     
    #1 constella, Jul 18, 2016
    Last edited by a moderator: Jul 18, 2016
  2. grayloon

    grayloon Well-Known Member

    Joined:
    Oct 31, 2007
    Messages:
    98
    Likes Received:
    2
    Trophy Points:
    8
    Location:
    Evansville, IN
    cPanel Access Level:
    Root Administrator
    Twitter:
    We have a nice, new vulnerability website to check out.

    Should we use Apache's recommended solution on our WHM servers?

    Code:
    The two lines below enabled in the httpd.conf file will remove the "Proxy:"
    header from all incoming requests, before further processing;
        LoadModule headers_module {path-to}/mod_headers.so
        RequestHeader unset Proxy early
    
     
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,678
    Likes Received:
    648
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    eva2000 likes this.
Loading...

Share This Page